Quantcast
Channel: Web Application Security Forum - Bugs
Viewing all articles
Browse latest Browse all 37

Re: possible bug

$
0
0
Albino Wrote:
-------------------------------------------------------
> I was thinking more along the lines that someone
> could post a link on here to their website and
> then see people's session_id in the referer. But I
> see your point, I'll just logout in future.

It's perfectly possible to circumvent this particular vector; sla.ckers could let all links go through a "link anonymizer" (like some *chan boards do).

Viewing all articles
Browse latest Browse all 37

Trending Articles